Re: Recommendations for replacing a master server without breaking DNSSEC

2021-11-26 Thread Ralph Seichter via bind-users
* Tony Finch: > I think a procedure like this is a good way to migrate a primary > server if the old and new servers are run by the same people [...] After reading your message I think that we used pretty much the same approach, although I am fortunate for not having to work under time pressure.

Re: Recommendations for replacing a master server without breaking DNSSEC

2021-11-24 Thread Tony Finch
Ralph Seichter via bind-users wrote: > > How would you go about moving all functionality from Alpha to Beta, > ideally with minimal downtime, and with the hard requirement of not > breaking DNSSEC? How would one need to handle key material, zone > signatures, journals, etc.? There was this time

Recommendations for replacing a master server without breaking DNSSEC

2021-11-23 Thread Ralph Seichter via bind-users
Hello list members. Imagine a BIND9 master-and-slave pair (let's call them Alpha and Omega, respectively) with automatic synchronisation in place. Imagine further that Alpha needs to be replaced by a brand new server Beta hosted in a different data center, which implies new hardware and